> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/dfiriris.md).

# Set up DFIR-IRIS credentials in Duaer

Store DFIR-IRIS connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Get a DFIR-IRIS API key <a href="#get-an-api-key" id="get-an-api-key"></a>

The Duaer DFIR-IRIS API credential:

1. In IRIS, click your user name at the top right, open My settings, and copy the API Key.
2. Put the IRIS web address in Base URL; the API shares its address and port, such as https://iris.example.com.
3. Turn on Ignore SSL Issues (Insecure) for a self-signed certificate.

Duaer has no dedicated node for this service. In the HTTP Request node, set Authentication to Predefined Credential Type and pick the DFIR-IRIS API credential. Refer to [custom operations](/integrations/custom-operations.md).

## DFIR-IRIS API fields in Duaer <a href="#dfir-iris-api" id="dfir-iris-api"></a>

In Duaer, choose DFIR-IRIS API when you create a credential, then fill in these fields:

- Base URL (required): The API endpoints are reachable on the same Address and port as the web interface.
- API Key (required, secret)
- Ignore SSL Issues (Insecure): Default: off.

When you save, Duaer tests the connection with these values.

## Save the connection in Duaer

Open Credentials and create DFIR-IRIS. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. 

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do DFIR-IRIS secret values appear in Duaer node parameters?

No. In Duaer, DFIR-IRIS secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a DFIR-IRIS credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields DFIR-IRIS expects, then confirm you can create credentials in that project.

